ZeroDayShield started as a backend experiment: could a single engineer continuously audit the four most malware-prone corners of the open-source ecosystem and publish findings in the open?
The pipeline now ingests every new artifact pushed to npm, Docker Hub, the MCP registry, and Hugging Face — runs them through a battery of static, behavioral, and ML-driven detectors — and surfaces the hits to a human researcher for triage and coordinated disclosure.
Every advisory you see in the feed went through that exact loop. No bug bounties. No paid embargoes. No vendor friendly massaging.